Skip to content

Your AI under GDPR and the AI Act: the answers your auditor needs, built into the architecture.

Where the data runs, what is logged and who can audit it, settled before go-live, for any AI that touches customers, staff or data in Europe, whether your company is European, American or British. Engineering work, not legal advice.

What already applies to your AI, and what comes next

The AI Act timeline after the Digital Omnibus: Article 113 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744.

What appliesFrom
Banned practicesFeb 2, 2025
Article 5.
General-purpose AI modelsAug 2, 2025
Model providers, governance, penalties.
Transparency dutiesAug 2, 2026
Article 50: people know they deal with an AI system.
Marking of generated contentDec 2, 2026
Article 50(2) for systems already on the market; new bans.
High-risk uses of Annex IIIDec 2, 2027
Employment, credit, education, essential services.
High-risk AI in Annex I productsAug 2, 2028
Machinery and other regulated products.

Engineering reading, not legal advice. The high-risk obligations moved in July 2026; the transparency duties did not.

Sources, read on EUR-Lex on September 28, 2026

Dates taken from Article 113 of the AI Act as amended by the Digital Omnibus on AI, published in the Official Journal on July 24, 2026. We re-check the text whenever it changes, and date this page again.

What is GDPR and AI Act engineering?

The part of compliance a policy cannot do on its own: deciding where personal data is processed, which model sees which document, what gets logged, how long it is kept and who can read the logs. Lawyers classify the use case and write the notices; engineers make the system behave the way those documents say it does.

Location does not take you out of scope: for a US or UK company with European customers, the engineering questions are those of a company in Lyon. The GDPR applies to a company outside the EU that offers goods or services to people in the Union or monitors their behavior there (Article 3(2)). The AI Act applies to providers placing systems on the EU market wherever they are established, and to providers and deployers abroad when the output is used in the Union (Article 2).

What each rule asks of your system, and what gets built for it.

Eight GDPR and AI Act provisions: what each asks in plain terms, and what is built into the system
Eight GDPR and AI Act provisions: what each asks in plain terms, and what is built into the systemWhat it asks, in plain termsWhat we build
GDPR, Art. 5(1)(c)Only the data the purpose needs.Fields a task does not need are masked before the prompt.
GDPR, Art. 28A contract with every processor.Every provider listed with its role, region and agreement, kept with the code.
GDPR, Chapter VRules for data leaving the EU.EU regions by default; any US provider written down with its transfer basis.
GDPR, Art. 17Erasure on request.A deletion reaches the database, the index, the logs and the caches.
GDPR, Art. 35An impact assessment when the risk is high.Its technical half: data flows, risks, what each measure does.
AI Act, Art. 5Practices banned outright.Each use screened before any code; banned uses declined.
AI Act, Art. 50People know they deal with an AI system.The interface says so; generated content is marked where required.
AI Act, Art. 12, 14, 26High-risk: logs, human oversight, six months kept.Who asked what, with which model; a person approves what commits you.

GDPR and AI Act (as amended in 2026), read on EUR-Lex on September 28, 2026. Engineering measures only: whether a use is high-risk is for your counsel to decide.

From your list of AI uses to evidence you hold.

Not an audit that ends in a report nobody implements: we build the system, or rework the one you have, and the evidence comes from building it properly.

  1. First week

    Each use case, with the facts your counsel needs.

    What data goes in, what comes out, who is affected, what decision it feeds. Your counsel classifies; the facts rest on how the system really works.

  2. Before the code

    The architecture note your auditor asks for.

    A data flow diagram, every provider and its region, what is logged and for how long, who can read what.

  3. During the build

    Controls built in, and tested.

    Masking before the prompt, access rights respected in retrieval, logging, human approval, notices in the interface.

  4. At handover

    Evidence you hold, kept current.

    A register entry per use case, read access to the logs, the technical annex of the impact assessment, a runbook.

100%platform availability over the program

Case study, measured over the duration of the operation

Expertise France, French government development agency

Code and hosting kept under the client's control.

The problem
Cameroon needed a national digital addressing base and a smart-city platform. The institution set one condition as non-negotiable: the source code and the hosting had to stay under its own control.
What was delivered
The addressing base delivered in production, the smart-city platform being delivered, a local project manager and two local developers trained, and the sources handed over so the country could host the platform itself. Not an AI system: the same discipline of control, applied to national infrastructure.
All case studies

What you sign for AI Act and GDPR engineering, in short.

Price
A fixed fee for a closed scope. We sell a deliverable, not days.
Hosting
EU regions by default; any exception written down with its transfer basis.
Evidence
The architecture note, the processor list and the register entries are yours, and change with the system.
Scope of our role
Engineering. Classification, notices and legal sign-off stay with your counsel.
Exit
Code, logs, accounts and documentation in your name, written for someone who was not in the room.
The commitments, with the limit of each

Who builds the controls your counsel will sign off.

Three senior engineers, two of whom have worked together for more than twenty years. We also run our own software in production, including a product that audits websites for compliance, security and accessibility: that is where we learned that a control nobody monitors stops being a control within a quarter.

  • Laurent Tulpan, founder of Coeur du WebLaurent, founder and CTOLists the use cases with your team and writes the architecture note.
  • Clairmont, technical leadClairmont, technical leadBuilds the hosting, the masking, the logging and the access controls.
  • David, frontend leadDavid, frontend leadPuts the transparency notices and the approval screens where people actually see them.

Scope, bans, US models, fines: answered in engineering terms.

What does EU AI Act compliance mean for a company that uses AI?

It depends on the role and the use case. A company that builds or sells an AI system under its own name is a provider; one that uses it in its operations is a deployer.

Most business uses, such as drafting, summarizing or routing requests, carry transparency duties rather than heavy obligations. Uses listed in Annex III, such as screening job candidates or assessing creditworthiness, are high-risk and carry obligations from December 2, 2027. A small set of practices is banned.

The first step is always the same: list the uses and classify each one.

Does the EU AI Act apply to US companies?

Often, yes. Article 2 of Regulation (EU) 2024/1689 covers providers placing AI systems on the EU market wherever they are established, and providers and deployers outside the EU where the output of the system is used in the Union.

A US software company that sells an AI feature to European customers, or a US employer that screens European applicants with an AI tool, should assume it is in scope and check its role.

Will the EU AI Act apply to UK companies?

Inside the UK it does not apply as such, since the UK is not in the EU. It does apply to a UK company whose AI system is placed on the EU market, or whose system produces output that is used in the Union, under the same Article 2.

A London firm with clients in Dublin, Paris or Amsterdam is in that position. UK GDPR continues to govern the personal data side at home.

What is banned under the EU AI Act?

Article 5 bans, among others:

  • manipulative or deceptive techniques that materially distort behavior and cause significant harm
  • exploiting the vulnerabilities of people because of age, disability or social situation
  • social scoring
  • predicting that someone will commit a crime from profiling alone
  • building facial recognition databases by untargeted scraping
  • inferring emotions at work or in education except for medical or safety reasons

These bans have applied since February 2, 2025.

Can we use ChatGPT or another US model API with European personal data?

Sometimes, and the answer lives in four engineering facts rather than in the brand:

  • Is there a data processing agreement with the provider?
  • Which transfer basis covers the data, for example certification under the EU-US Data Privacy Framework, which the EU General Court upheld on September 3, 2025, in case T-553/23?
  • Can processing stay in an EU region?
  • Does the task need the personal data at all?

When it does not, masking it removes most of the problem. For sensitive material we default to models hosted in the EU or on your own infrastructure.

What are the fines, and do you give legal advice?

Under the AI Act, up to 35 million euros or 7% of worldwide annual turnover for banned practices, and up to 15 million euros or 3% for most other obligations, whichever is higher (Article 99). Under the GDPR, up to 20 million euros or 4% for the most serious infringements (Article 83).

We do not give legal advice, sell a compliance certificate or classify a high-risk use on our own authority: that belongs to your counsel and your data protection officer. We hand them a system that is already documented.

Name the AI use case that worries your counsel. We map where its data goes.

20 minutes to see what it would take to make the system auditable. If a policy change is enough, we say so.

A 20-minute video call